Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

151–160 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#151
post #149

Earlier quoted context omitted.

That doesn't seem to be a problem for protocols and having a single implementation can lead to bugs that defy spec yet cause no issues obviously.

But you're not branding or selling implementations

*protocols

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#152
post #143
post #139

Earlier quoted context omitted.

> Too bad they lack either brain cells or basic human empathy to make a connection between these events. I think that's giving them too much benefits. They know what they're doing, it's clear they want "security for me, but not for you", and claiming they're too dumb to know exactly what they're doing is playing it exactly like how they want it.

Yeah, that the "lacking empathy part". Most of them are sociopaths and psychopaths, in the medical sense. They only want power for themselves at any cost to others.

I don’t think it’s that extreme. They probably view themselves as the arbiters of society and are inherently granted more privilege than a normal citizen. Paternalistic more than sociopathic. Issue is our parents, while have the benefit of experience, don’t know shit about shit really. Especially when it comes to tech.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#153

Wow, this whole TeleMessage leak feels like a spy thriller.

if you get your spy thrillers from Mexican day time tv soap opera script writers, yes.

Telenovella about spy’s? Sign me up.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#154
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Is this a heapdump of servers or of clients? I can imagine that might have been intended as a place for crashing clients to log

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#155

Isn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.

Based on pure guesswork I'd say that you higher up the person, the less the rules apply.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#156
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

> They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

That's very important to say. I went through one of these massive data dumps recently and it was literally all cached operating system package updates and routine logs. Nothing at all of interest.

It's easy to cut the size on a heap dump. When it's not done it seems sketchy. But it could be a 512GB dump and already pruned, so I could be wrong.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#157

Earlier quoted context omitted.

This just reads like a terrible LinkedIn-speak to me.

Sufficiently advanced human written linkedin-speak is indistinguishable from a barely coherent chatgpt 3.5 that's been instructed to speak in business buzzwords.

Overly polished language, abstract phrasing, and a focus on generalities over specifics.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#158

Earlier quoted context omitted.

From the Wired article, it may not have even been a mistake, depending on the version of Spring Boot. "Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."

Imaging putting up a firewall to mitigate this, then docker compose helpfully opening the ports for you. Security comes in layers.

This feature of docker compose is insane.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#160
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

TeleMessage is most likely an intelligence asset, and a burned one now that Trump's people stopped using it. A fake hack is the safest way for the agency responsible to leak the messages collected.
Post reply on HN